IP Library Granted Patent US 10,165,055
Granted Patent B2
US 10,165,055 · App. 15/191,900 · Granted Dec 25, 2018

Systems and methods for network controlled access of resources

Inventor: Pravin Singhal (San Jose, CA)
Assignee: Citrix Systems, Inc.
H04L67/141H04L63/0272H04L63/10H04L63/20H04L67/02H04L67/025H04L67/04H04L67/18H04L67/28H04L67/42H04L69/16H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,165,055
App. No.
15/191,900
Granted
Dec 25, 2018
Kind
B2
Abstract

The present disclosure is directed to systems and methods for controlling delivery of a resource. An intermediary device may establish a connection to deliver a resource hosted on at least one server to a client using a remoting protocol. The remoting protocol may define one or more channels in the connection for delivering or enabling one or more features of the resource to the client. The device may identify the one or more channels, and may identify the one or more features of the resource. The device may determine a policy for controlling access of the client to at least a first feature of the resource. The device may control access of the client to the first feature by modifying a first channel of the one or more channels according to the determined policy.

Claims (27)

1. A method for controlling delivery of a resource, comprising:

establishing, by a device intermediary between a client and at least one server, a connection via the device to deliver a resource hosted on the at least one server to the client using a remoting protocol, the resource comprising at least one of an application or a desktop executing on the at least one server, the remoting protocol defining a plurality of channels in the connection for delivering or enabling one or more features of the resource to the client;

identifying, by the device, the plurality of channels in the connection defined by the remoting protocol and the one or more features of the resource to be delivered or enabled by the plurality of channels;

determining, by the device, a policy specifying a first channel of the plurality of channels and for controlling access of the client to at least a first feature of the one or more features of the resource, the first channel for delivering or enabling the first feature of the resource to the client; and

controlling, by the device, according to the determined policy, access of the client to the first feature of the resource by modifying the first channel of the plurality of channels for delivering or enabling the first feature of the resource to the client.

2. The method of claim 1 , further comprising identifying, by the device, one or more elements or processes of the plurality of channels that are modifiable by the device.

3. The method of claim 1 , further comprising identifying, by the device, one or more features of the resource to be delivered or being delivered via the connection.

4. The method of claim 1 , wherein each of the plurality of channels is configured to deliver or enable at least one feature of the resource to the client.

5. The method of claim 1 , wherein determining the policy for controlling access of the client comprises determining the policy based on at least one of: a geographical location or a result of an end point analysis (EPA) of the client.

6. The method of claim 1 , further comprising inspecting, by the device, one or more packets transmitted via the plurality of channels of the connection.

7. The method of claim 1 , wherein modifying the first channel comprises modifying an element or process of the first channel during establishment of the connection or after establishment of the connection.

8. The method of claim 1 , wherein modifying the first channel comprises modifying the channel so that the server does not initialize the first feature of the resource.

9. The method of claim 1 , wherein modifying the first channel comprises modifying an identifier or a name of the first channel.

10. The method of claim 1 , wherein determining the policy for controlling access of the client comprises determining the policy during establishment of the connection.

11. A system for controlling delivery of a resource, comprising:

a connection engine executing on a device intermediary between a client and at least one server, the connection engine configured to establish a connection via the device to deliver a resource hosted on the at least one server to the client using a remoting protocol, the resource comprising at least one of an application or a desktop executing on the at least one server, the remoting protocol defining a plurality of channels in the connection for delivering or enabling one or more features of the resource to the client;

a remoting protocol engine executing on the device, the remoting protocol engine configured to identify the plurality of channels defined by the remoting protocol and the one or more features of the resource to be delivered or enabled by the plurality of channels;

a policy engine executing on the device, the policy engine configured to determine a policy specifying a first channel of the plurality of channels and for controlling access of the client to at least a first feature of the one or more features of the resource, the first channel for delivering or enabling the first feature of the resource to the client, and to control, according to the determined policy, access of the client to the first feature by modifying the first channel of the plurality of channels for delivering or enabling the first feature of the resource to the client.

12. The system of claim 11 , wherein the remoting protocol engine is further configured to identify one or more elements or processes of the plurality of channels that are modifiable by the device.

13. The system of claim 11 , wherein the remoting protocol engine is further configured to identify one or more features of the resource to be delivered or being delivered via the connection.

14. The system of claim 11 , wherein each of the plurality of channels is configured to deliver or enable at least one feature of the resource to the client.

15. The system of claim 11 , wherein the policy engine is further configured to determine the policy based on at least one of: a geographical location or a result of an end point analysis (EPA) of the client.

16. The system of claim 11 , wherein the remoting protocol engine is further configured to inspect one or more packets transmitted via the plurality of channels of the connection.

17. The system of claim 11 , wherein the policy engine is further configured to modify an element or process of the first channel during establishment of the connection or after establishment of the connection.

18. The system of claim 11 , wherein the policy engine is further configured to modify the channel so that the server does not initialize the first feature of the resource.

19. The system of claim 11 , wherein the policy engine is further configured to modify an identifier or a name of the first channel.

20. The system of claim 11 , wherein the policy engine is further configured to determine the policy during establishment of the connection.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2016
From: SINGHAL, PRAVIN
To: CITRIX SYSTEMS, INC.
Reel/Frame 040043/0851 →
Continuity (2)
Provisional Application 62186695 · Jun 30, 2015
Related Publication 20170006113A1 · Jan 5, 2017